Thanks for the well-documented video-can't believe I'm finding it 11 years after it was posted! Haha!
@professorfrank Жыл бұрын
Awesome because the Cisco document is missing the export command
@doncrawley Жыл бұрын
I'm glad it was helpful. Thanks for your comment.
@soundtraining11 жыл бұрын
Apologies for the delayed reply. The FQDN is how the device is identified via its certificate. It doesn't require a DNS A record, but without an A record or an entry in a local hosts file, there would be no point in having the certificate to prove name-based identity. I've never used an IP address with a certificate, but I don't know why it wouldn't work. In fact, there are some CAs that offer that service. Obviously, that would eliminate the need for either an A record or a hosts file entry.
@soundtraining11 жыл бұрын
The CA certificate is generated by the device you wish to configure as a certificate authority, such as a Windows Server 2012 computer or a Linux computer. The certificate can either be self-signed or signed by an upstream certificate authority such as Verisign, Comodo, GeoTrust, or any of the many other CAs. If you visit any of the CA websites, you'll find more information about the process.
@tompinkerton80993 жыл бұрын
Excellent video! It helped me out immensely.
@soundtraining11 жыл бұрын
It's been a while, but I think I got that one from DigiCert. You can get trial certs from lots of providers and most of them should work similarly to what you see in the video.
@georgiev8511 жыл бұрын
So for the "Certificate Subject DN": - does the FQDN need to have an A record in DNS? - can we use an IP instead? I guess I am not sure what the FQDN is used for in this case.
@Breto15111 жыл бұрын
So just to make sure I have this right you got both certs from Digicert? I have been trying to setup my own Windows 2008 CA to do a similar VPN design. I wasn't sure if the 2nd cert was from Digicert or it was created from something else that I missed.
@brandonfontaine2852 жыл бұрын
How is this done without ASDM? My CF card cannot hold asa and asdm image
@cloudwaf-fbi3 жыл бұрын
very good,good job
@ismailrajaallah166711 жыл бұрын
hi can you tell me how to have a ca certificate
@Breto15111 жыл бұрын
Where did you get the ASA_soundtraining cert from?
@heraldsison54105 жыл бұрын
Hi Sir, i have encountered a problem when installing certificate. i have already generated CSR and comodo already replied to us the certificate, i have also uploaded the CA certificate that comodo gave us. but when i try to install the cert in identity certificate the "Install Button" is greyed out. How can i fix this sir? i really want this to be done within today but i am stucked to this portion, i have attached a screenshot for your reference. Thank you so much, Your reply is much appreciated.
@branimirkarajcic783911 жыл бұрын
What is the purpose of that default key that is generated? I would think it is because of SSH, but it is not since to get SSH to work it is still needed to generate RSA key.
@rohanacharekar928 жыл бұрын
Hi Don thanks a lot for the video. Just wanted to know if you have uploaded the following video on how to associate the certificate with the remote access vpn ??????
@muriloninja7 жыл бұрын
Remote Access VPN->Advanced->SSL Settings...then assign it to the Outside interface, it will show up in a list there once you highlight the interface and click edit.
@immenseTie7 жыл бұрын
Can I plz get a answer also.....has the next video been released... associate certificate with the remote access vpn
@malcontentman98207 жыл бұрын
When going to install the asa01_soundtraining_crt cert, how was that generated? I think I am missing a step. Many thanks!
@ishanmishra438610 жыл бұрын
i have received 2 certificated from my CA..intermediate & ssl certificate..which certificate should i install in identity certificate & which one should i install in CA..
@timbatec10 жыл бұрын
is there any easier way to validate that certificate?
@RaissaMarconConstante9 жыл бұрын
Hi, excellent video! Could you publish the commands used behind ASDM to install the certificate? I'd really like to know the commands. Thank you!
@soundtraining9 жыл бұрын
+Raissa Marcon Constante My apologies for the delay in responding. I just now noticed your question. In the ASDM, there is an option to preview commands. Look under Tools>>Preferences>>General.
@mghebremichael8 жыл бұрын
Hello,I am wondering if I can use VPN Digital Certificate on my Both ISP interfaces.... do I need to generate key for each ISP interface?
@AngyOtt9 жыл бұрын
Do you need a certificate to perform in-class exercise with VPN?
@soundtraining9 жыл бұрын
+Paul Kim Older versions of the software did not require a certificate. I couldn't find a way around it in version 9.x. For demonstrations, I either get a trial certificate or set up a certificate server and generate my own. Thanks for your questions.
@AngyOtt9 жыл бұрын
running ASA 832 (can't recall perfectly) so IPSEC/Anyconnect VPN should work just fine, right? Thank you for your answers :D
@mudslide13511 жыл бұрын
So I generate the key then go to entrust and paste the csr and it keeps giving me the error -null is not a lid country code...what does this mean? Would it be related to not having my home network on a configured domain. Just bough the the asa and am trying to set it up to play around with at home
@xphobe9 жыл бұрын
+Justin C (K1m0ra) You have to have a valid public DNS domain name associated with the public outside IP of your ASA. You can get one free from dyndns.org, which has the added benefit of being able to track your IP even if you get one via DHCP from your isp, and keeping your domain name registered to it.
@Asianredneck10009 жыл бұрын
I saw that he saved the self generated as a TXT file not as a CRT. Do I go back and save the file as a crt? I did not see where he saved the asaol.soundtraining.net.crt certificate. Little confused where he got that asao1.soundtraining.crt file from. Was that from digicert? Anyone can help?
@xphobe9 жыл бұрын
+Tyson Vu Yes, he got it from digicert. Remember, he got two: the intermediate or chain cert file, and also the identity cert file. When he installed each one, he browsed to where he had saved the files. He did mention that you cannot see the extension, but it is .crt.
@phuckewe1789 жыл бұрын
I get a message that reads WARNING you already have a RSA key name Default ASA Key. Is this different than the SSL certificate we're generating?
@soundtraining9 жыл бұрын
+Phuck Ewe No, the message means you're replacing the default key. You don't actually have to generate a new default key, but I wanted to show the process for generating a key. I just did it that way for the demonstration. Sorry I wasn't more clear about that in the video.
@rachidfa63768 жыл бұрын
I have an ASA 5510 Version 8.2 (5) with the following config Hardware: ASA5510 1024 MB RAM, CPU Pentium 4 Celeron 1600MHz Internal ATA Compact Flash, 256MB my question I want to install Annyconnect vpn with this config. is that it is compatible with the prerequisites to install annyconnect with 256mb flash?Maximum Physical Interfaces : Unlimited Maximum VLANs : 100 Inside Hosts : Unlimited Failover : Active/Active VPN-DES : Enabled VPN-3DES-AES : Enabled Security Contexts : 2 GTP/GPRS : Disabled SSL VPN Peers : 2 Total VPN Peers : 250 Shared License : Disabled AnyConnect for Mobile : Disabled AnyConnect for Cisco VPN Phone : Disabled AnyConnect Essentials : Disabled Advanced Endpoint Assessment : Disabled UC Phone Proxy Sessions : 2 Total UC Proxy Sessions : 2 Botnet Traffic Filter : Disabled thank you
@kelloggfan10 жыл бұрын
following your every move - you make it look easy but for 2 days I am getting the following error: Cannot import certificate - Certificate does no contain device's General Purpose public key for trust point ......ERROR: Failed to parse or verify imported certificate. What could be wrong - I am following exactly every move...??
@soundtraining10 жыл бұрын
Which ASA software version are you running?
@kelloggfan10 жыл бұрын
soundtraining.net I am running 8.2(5) ASDM 7.1(6)
@soundtraining10 жыл бұрын
William Rossetti William, that's a really old version of the ASA software. The video is based on version 9.11. If you can't upgrade, check out the Cisco documentation at www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/cert_cfg.html
@kelloggfan10 жыл бұрын
so are you saying the older version won't work?
@soundtraining10 жыл бұрын
soundtraining.net Not at all. What I'm saying is that the video is based on software version 9.11 and you're working with version 8.25. There are probably differences in the commands and it's been a long time since I've worked with version 8.25, so I don't remember the syntax for that version. That's why I posted the link where you could get the correct syntax for the version you're using.
@minhtruong693512 жыл бұрын
love it...thanks
@mayankdhingra40868 жыл бұрын
font size is very small very diffult to see the configuration